Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hamid ebadi vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2006-0502
PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and previous versions, with register_globals enabled, allows remote malicious users to include arbitrary files via a URL in the cutepath parameter.
Farsinews Farsinews
1 EDB exploit
4
CVSSv2
CVE-2006-3184
Direct static code injection vulnerability in ASP Stats Generator prior to 2.1.2 allows remote authenticated malicious users to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.
Asp Stats Generator Asp Stats Generator
1 EDB exploit
5
CVSSv2
CVE-2007-2252
Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and previous versions allows remote malicious users to obtain sensitive information via a .. (dot dot) in the icodir parameter.
Exponent Exponent Cms 0.96.5 Rc1
Exponent Exponent Cms 0.96.6 Alpha
1 EDB exploit
7.5
CVSSv2
CVE-2009-4018
The proc_open function in ext/standard/proc_open.c in PHP prior to 5.2.11 and 5.3.x prior to 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent malicious users to execute programs with an arbit...
Php Php 4.3.1
Php Php 4.3.2
Php Php 4.1.0
Php Php 4.2.1
Php Php 4.4.7
Php Php 5.0
Php Php 4.3.9
Php Php 4.4.0
Php Php 5.0.4
Php Php 5.0.3
Php Php 5.0.0
Php Php 1.0
Php Php 4
Php Php 3.0.2
Php Php 3.0.18
Php Php 4.0
Php Php 3.0.9
Php Php 4.0.1
Php Php 4.0.5
Php Php 4.0.4
Php Php 4.3.11
Php Php 4.3.4
1 EDB exploit
7.5
CVSSv2
CVE-2006-3580
SQL injection vulnerability in pages.asp in ASP Stats Generator prior to 2.1.2 allows remote malicious users to execute arbitrary SQL commands via the order parameter.
Asp Stats Generator Asp Stats Generator
1 EDB exploit
5
CVSSv2
CVE-2008-5498
Array index error in the imageRotate function in PHP 5.2.8 and previous versions allows context-dependent malicious users to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.
Php Php 5.1.3
Php Php 5.1.2
Php Php 5.2.1
Php Php 5.2.2
Php Php 5.0
Php Php 5.0.2
Php Php 5.0.1
Php Php 5.0.0
Php Php 5.2.6
Php Php 5.2.5
Php Php 5.1.6
Php Php 5.2.0
Php Php 5.0.4
Php Php 5.0.3
Php Php
Php Php 5.1.1
Php Php 5.1.0
Php Php 5.0.5
Php Php 5
Php Php 5.2.7
Php Php 5.2.4
Php Php 5.2.3
1 EDB exploit
7.5
CVSSv2
CVE-2006-7021
PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote malicious users to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter.
Plume-cms Plume Cms 1.1.3
1 EDB exploit
7.5
CVSSv2
CVE-2006-1081
SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote malicious users to execute arbitrary SQL commands via the email parameter.
Jonathan Beckett Pluggedout Nexus 0.1
1 EDB exploit
5.1
CVSSv2
CVE-2006-3361
PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and previous versions, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDIP paramet...
Stud.ip Stud.ip
1 EDB exploit
6.4
CVSSv2
CVE-2006-0660
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and previous versions allows remote malicious users to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbi...
Farsinews Farsinews 2.1
Farsinews Farsinews 2.1 Beta2
Farsinews Farsinews 2.5
2 EDB exploits
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2